If you do run Windows, be sure to check that your TPM/SecureBoot devices are enabled, and that Core Isolation/Code Integrity (for example, Hypervisor Enforced Code Integrity) is enabled if possible. Unfortunately, this setting can sometimes cause driver incompatibilities and enabling it via the registry manually may be experimental/crashprone.
https://learn.microsoft.com/en-us/windows/security/threat-pr...
Network-based IDS helps a lot in this area -- something like pfSense with pfblocker-ng + Suricata. Unfortunately, there is also malware that can masquerade protocol/etc: https://www.cisa.gov/news-events/cybersecurity-advisories/aa...